Todd Schiller

Human ✘ Artificial Intelligence

A lightly edited transcript of my August 2026 conversation with David Dean Mauro on the Cyber Crime Junkies podcast. Watch on YouTube.

The transcript was produced with Whisper and lightly edited.


David Dean Mauro: Everybody thinks the smarter the AI is, the safer you are. It turns out the opposite. Researchers at Stanford found the smarter the model, the more it thinks, the easier it is to con. Because it wants to finish the job so badly, it'll talk itself into being scammed, into being socially engineered. The same cheap tricks that fool a distracted employee, the AI falls for it too. And then it acts on your behalf.

Now, hand that agent your files, your intellectual property, your searches, and your data. One planted instruction and it'll walk all of your secrets, all of your special sauce, right out the door, politely.

I sat down with Todd Schiller, cybersecurity expert, the guy building the guardrails for exactly this topic. And what he told me will scare every one of us that is trying to run with AI before learning to crawl. Watch all the way through to find out what they don't want us to see.

This is Cyber Crime Junkies. And now the show.

All right. Well, welcome, everybody. This is Cyber Crime Junkies. I'm your host, David Dean Mauro, and in the studio today is a remarkable founder, CEO, breadth of experience, Todd Schiller. He's the co-founder and CEO of PixieBrix, the platform for contact centers and other organizations that protect revenue and data and also provides cybersecurity for AI agents right in the browser. We're going to talk about that.

He holds a PhD in computer science from the University of Washington, so I will ask him to break down the words he may use so that the host can understand. And he has focused his career around automated program analysis. He also holds a master's degree in machine learning. Dude, I want to say, where did this come from? This is good. That is strong education. They did not have that when I took math for rocks in college, back then. You're a lot younger. So this is great. Welcome to the studio, my friend.

Todd Schiller: Great to be here, David.

David: When we were first talking, we were talking about addressing insider risk, and I would like to start there if that's okay, if you'll permit me.

Todd: Absolutely.

David: Okay. Before we get there, walk me through how did you know to get your education in these fields? What drove you? Is there an event when you were younger? Was one of your parents into it? Did you have a mentor? How did you first come to be passionate about this?

Todd: My parents were not in technology, both parents in the medical field. I have two older brothers, and so I got to see everything that they were doing. When my older brother took a programming class, I could see what that was. Like a lot of kids, I was into computer games. But what I found more interesting than the computing games themselves was, how could you modify them? So there were mods, there were hacks that you could download, all of those to influence that. Even The Sims had some fun mods that you could put on to get in the hex editor and change your career salary or give yourself more points, etc. So I got bit by the programming bug.

As I was going towards college, I was deciding, given my parents were in the medical field, between the medical field and maybe computational neuroscience versus pure programming. From there I had the opportunity to shadow different doctors and decided this isn't for me, or at least clinical work is not for me. And then when I got to college I was pre-med and decided, based on my chemistry scores and other things, chemistry is not for me and medicine's not for me. So let me focus on the core computer parts that I enjoy. And it's about, what were you spending your time on weekends on, what were you spending your nights on? How can you turn that into a career? That led me there.

David: What type of medical professionals were your parents?

Todd: So my dad was an ER physician, a different sort of career. And then my mom ran a blood lab at a hospital.

David: Okay, excellent. More R&D and analysis, forensics, things like that.

Todd: And then management around how do you make sure that you're tracking all the specimens and other pieces, getting those results out and on time. But even though they weren't in technology, they had the foresight. We had an Apple IIgs, and then a 386. So we always had a household computer, even if I was restricted maybe to one hour a day, or you'd have to go outside before you could come back and do another hour on the computer.

David: That's fantastic. Thanks for that background. That explains a lot. I also had two older brothers. And I went into one of the fields originally as one of my brothers, which was standing in the pits of the trading pits back in the day and screaming our heads off, because to me that seemed fun and it was. But then technology came and made it all electronic trading. Anyway.

Insider risk. When we talk about insider risk in your experience, explain the context, because there's various forms of insider risk. There's corporate espionage, there's fraud, there's refund fraud, there's pay card fraud, and cyber crime organizations segment just like businesses do.

Todd: Absolutely. So we primarily deal, and my experience is primarily with, contact center business process outsourcing. I like the episode that you did with Shani Delaney. She broke it down well in terms of even insider risk versus insider threat.

On the insider risk side of things, if you look at it more broadly, people are fallible. And they can be fallible either on accident because they're overworked, they have a lot of things to do, the processes are complicated that they have to deal with, or maybe they're being trained. So they might make mistakes. And this happens in the financial field as well. They might fat-finger a number, which can cost the business a lot of money. And then you have the more fraud-like activities where they're cognizant of doing something that they're not supposed to be doing.

In the contact center, we see three or four main categories of that. One of those would be refund or price fraud. So are they giving refunds that they're not supposed to? Are they changing the price of things in a way that they're not supposed to? The second one would be address fraud. So are they shipping something to a place they're not supposed to? Are they shipping it to themselves, friends and family? I have a lot of interesting stories of the extent that people will go to there. There's also loyalty program fraud and gift card fraud. These folks are seeing gift card numbers and other things come through, and those are cash that can be misappropriated. And then you also, in certain areas, get snooping or exfiltration sorts of things. So in healthcare, you have HIPAA and certain regulations and technologies around how do you make sure that someone who's not supposed to access a medical record has restricted access to that record. In e-commerce and other places, it's much more wild west in terms of which records are you allowed to look at, but you could still have interesting information about a celebrity, a VIP, or other folks.

For each of those categories, there's benign mistakes that you could make. You could give the wrong refund, or you might want to get a customer off the phone quickly, and so you're going to give them a refund even though it's out of policy. And then there's the fraud version of each one of those as well. Being able to detect both of those cases is essential to protecting the revenue and integrity of a business.

David: And in terms of the loyalty, this goes beyond retail. It extends across various different industries. As you mentioned, HIPAA in the healthcare field, dealing with EHRs and EMRs and misconfigurations, all of the wrong access to private healthcare, private PHI. I did see oftentimes there were a lot of investigations and cases involving logistics firms with the loyalty programs. You think of the truckers and the loyalty programs and how there was a lot of fraud with that, because, you explained, this turns into cash. It can turn into cash for goods or pure cash.

What are some of the cases that you got involved in, and in what context did you get involved? Were you involved at the contact center, meaning the people answering the phones or processing? What level were you involved and what are some of your experiences?

Todd: Yeah, absolutely. So we're always involved at the contact center level, whether that's directly with the brand or with one of the business process outsourcing vendors that they use for contact center.

David: Makes sense.

Todd: And for people who aren't familiar with the industry. If I'm a brand, an e-commerce brand, I might do some of the customer support in-house myself. But I may farm it out, either within the United States or to a lower cost geography, or to a firm that specializes in recruiting talent and experienced people to provide that kind of support, especially if I need foreign language support for some of the cases, or I have a highly seasonal business. So I need to spike demand, or spike my supply of customer support.

And that's where you get into, there's some innovative business process outsourcing firms that we work with that provide that sort of elastic supply of customer support, where they use gig workers who bring their own device, or buy a device from that business process outsourcing firm, so they can get some extra hours in nights and weekends to supplement their income. But that's essential when you have a big event for your e-commerce firm, like a sale or Black Friday, to be able to provide that capacity.

David: I always have the balance between convenience and security. We always talk about that here. And when organizations are in growth mode, which most organizations are, they want the convenience features. They want to employ people through the gig economy, and they're not necessarily thinking about security. We don't want to be the mayors of the town of no and say, no, you can't do that. But you have to find ways to do that. And oftentimes it's filling a void, or piecemealing, patching together different solutions to solve the problem in a cost-effective way so that they can continue to grow. Is that what you've seen in terms of ways to help the business leaders as they want to grow?

Todd: Absolutely. We see two categories of companies that are the most vulnerable. One of those are those high-growth companies, as you mentioned. They're growing at all costs. They don't have a CISO early on. So it's when they get ready to IPO, or their later rounds of fundraising, when they start getting governance and other things in place.

David: Due diligence, they have to answer those questions.

Todd: Yeah, exactly, that they come up the scale there. The other one that we see is maybe legacy companies that started pre-internet, that they have these order management systems or ERP systems that were never designed to have fine-grained access controls.

David: No, and a lot of them are proprietary.

Todd: Yeah.

David: A lot of them they built themselves, or they had a developer or two, or their IT person, I've seen, developed the proprietary system.

Todd: Yeah, and they can't make changes to them anymore. So a lot of what we see, whether it's accidents or mistakes or the fraud, is taking advantage of the fact that when you call with a customer support complaint, it's not like healthcare where there's a single EHR that the person's interacting with. They're interacting with seven or eight different systems in order to solve the case. Each of those has a different granularity of permissions and access controls. And so a lot of the issues come from not necessarily the systems being misconfigured, but people taking advantage, and sometimes it's called business logic abuse, of, if you look at each thing in isolation, it's fine. It's not ringing any alarm bells. It's how the person combines those together in order to have an effect that leads to a bad outcome for the business.

David: That's interesting. I never thought about that, because I'm not in that space in my day job. But that's a good point. They might need to solve a customer complaint. They might need to see history of financials involving that. They might need to see early communications. And now they're accessing different systems, which in a vacuum is perfectly innocent. It's benign. But giving a gig worker access to financials can be a problem, if there's malintent.

Todd: Yeah, absolutely. And so you see different cost versus benefits that folks try. The most locked down that you might do is use a virtual desktop infrastructure like Citrix or other pieces. That's going to be the most expensive for the brand to offer. And then it's also the worst customer experience, because they're often slow and under-resourced.

David: And expensive to maintain and manage over time.

Todd: Exactly. And so what we're seeing now is a shift, especially as work has moved from desktop applications to web applications, people trying to figure out how do we lock down the browser as the endpoint, potentially with another agent running on the operating system. But if all the work's going to be done in the browser anyway, how do we use a secure browser versus an entire desktop environment that we're shipping?

David: Absolutely. And I've seen an influx of enterprise browsers that are in the market. Share with us some of the stories that you've been involved in in terms of insider risk. What are some examples that people could hear about that they may never have thought about happening?

Todd: Yeah, absolutely. So we're talking about different grades on each of these. On address fraud or location fraud, there's this element of, I am going to ship a product somewhere. I have a customer on the phone. I might change that address to be shipped to myself, or shipped to a family member or a friend. And so the customer doesn't receive it and they wonder why they don't receive it. That one's a bit easy to detect because you could have a database of all your employees' addresses. You might need to do some normalization. They might leave off the apartment number so they can grab it from their apartment building. If they're sending it to a family member or a friend, that might be trickier, because you might not have that family member or friend in the database. But if you look at, they're sending these addresses to the same address or same area frequently, maybe there's something suspicious going on there.

And then, the most complex that we've seen is, someone knew what the route was for the UPS or the FedEx truck in their area, and so they would send it along that route, so then they could follow the truck and steal the packages from the doorsteps of where they were sending it to.

David: So they were involved in the customer service element, then they became a porch pirate.

Todd: Yeah, exactly.

David: Wow.

Todd: Yeah, and then, the reason why those are hard to detect is, there's regulations. There's PCI DSS, which is the standard for security around payment details, and the address, depending on how you consume it, is part of the credit card information about that card holder. And oftentimes you will have a different bill-to and ship-to address. You have to be careful about how you're handling addresses. So what you might do is say, for every address that the agent touches, let me geolocate that, and so if I see that there's a cluster that seems unusual, maybe I would flag that for investigation. But the thing is, in large cities you do, because there's a lot of people that might be living in a building, you still get false positives, because there may be customers living in the same building as the agent, etc. So it's tricky to do in a way that's compliant while still getting the right kind of false positive rate on things.

David: Interesting. And in terms of AI and how AI has changed so many things, the way we operate and the way that we're able to derive intelligence and slice data. As organizations evolve along the scale in AI, they go from generative to building workflows, and then they start to build agents in various forms. And as they do that, the risk seems, in our experience, to increase exponentially, because agents aren't given a prompt with an immediate, or at least they can be set up without a human in the loop at every stage, and they become autonomous and they start working and they go and they complete that mission. And we've seen some examples where, despite the instructions given, the agent will bypass systems and still access things it shouldn't have. So what have you developed, what have you seen in terms of that scenario?

Todd: Yeah, so AI has been disruptive to the contact center industry and outsourcing in a lot of different ways. It evolved both the insider threat landscape and also the outsider threat. So on the outsider threat side, now it's made voice phishing a lot easier. You have deepfakes and other pieces of, how do you prove identity in this case, especially for password resets, SIM changes or resets, or other pieces.

And then even customers being in the mix as well. You used to have fake insurance claims, or fake refunds, or other pieces of people abusing those sorts of things. Now, it's easy to take a photo and doctor the photo, so that you get a refund or say that something was damaged. Also, in your case, you have folks going into the customer support chatbot on a site and doing a certain set of instructions to trick that in order to give them a refund or give them a different price, etc. This whole community is on, how do we, what is the right language you need to use for a certain bot to get it to give you a deal or a discount?

David: Because now they're on the dark web, they're on Telegram. They show you how to do it. You're socially engineering the AI LLM, the chatbot itself.

Todd: Exactly. And the legal precedents, probably not in the US, but at least in Canada and some other countries, is, if the AI chatbot is giving you a price quote, that is a legally binding price quote.

David: I explain this to the SMB space often because they don't understand it sometimes. If a company sold a car without brakes, or with defective parts, they would have to have recalls, there would be liability on the manufacturer. But when organizations roll out AI, all of the regulations, it's caveat emptor. It's buyer beware. You are liable for what that chatbot does, generally speaking.

Todd: Absolutely. And it's up to organizations to understand, what is that right mix of what sorts of cases should be handled by that chatbot? For example, password resets, one of the most common things for SaaS companies or software companies to deal with. If you can get a flow that's safe there, use the chatbot for deflection. In those cases, the people want to handle that fast. And then, more sophisticated organizations. Google, you can label yourself as an at-risk individual, maybe because you're a journalist and targeted by nation-state actors or other folks. So then there's additional things that you need to do, show a government ID or other pieces to reset that password. It's, try to take a practical approach for which thing you're putting on to the AI bot versus which thing that you're still having a human handle.

And in there, we see, a lot of these companies, out of the gate, they're like, oh, we can save money, we're going to have an AI handle everything. The issue there is, some people do like the fast handling, but it also decreases customer loyalty, because now you're not getting that human touch point with the business where they can show empathy for what has happened. And then also, for larger purchases, especially travel, leisure, other things, are you going to trust the chatbot to rebook your flight, your family vacation that you get once or twice a year? Or are you going to want to talk to a human for that sort of flow? So companies need to figure out what are the high-value places and touch points that they can use customer support for to grow the relationship.

David: What is the void that you saw, the gap in protecting AI agents, protecting organizations from either a compromising AI agent or an AI agent going rogue? And what was the impetus for creating PixieBrix? Walk us through it and tell us what it is from a high level, and then we can get down into the granular detail.

Todd: So what PixieBrix is, there's three big parts to it. One is a control plane where you can set different policies, and it could be by function, line of business, or by seniority. What we were talking about earlier was, the problem with a lot of these different systems is that they were never set up to have fine-grained access control. Everyone gets the keys to the kingdom when you log in.

The second piece is we have a browser extension that sits on the device that can then understand what are the actions that you're doing in every single tab of that browser and how they relate to each other. So whether I'm on a dialer like Five9 or Genesys in a customer interaction, what am I doing in my order management system or ERP, what am I doing in maybe a third-party logistics supplier portal, what am I doing in the knowledge reference that I'm dealing with. The big gap that a lot of folks can't handle with previous technologies is, how do you understand what's happening in those applications and how it relates to each other? Because a lot of folks will lock down their Salesforce or their dialer, but it doesn't then have context on what else the agent's doing, and that they're logging into the order management system when they're not supposed to be.

So big pieces of what we then enable are things like what's called transaction matching, or interaction matching. What is the justification for why a person should be accessing David's record? Do we have any evidence that they're dealing with a customer support ticket involving David, right before accessing that system?

David: So it can make that determination and then either grant the permission, or is PixieBrix able to allow permissions or adjust permissions, based on how it's designed?

Todd: Yep, so there are generally four levels that folks look at. So it's monitoring. When you set up a security tool, like a web application firewall or other things, you might monitor everything, and see, what's going on in my organization. The second would be warning. So do I need to send out something to a manager, or the security team, or that particular agent's manager who's watching that shift? Then there's soft blocking. So can you pop up something to that agent and say, this is unusual, can you give me the reason why you're accessing this? So you have that attestation from that agent that they're supposed to be performing that action. And then the fourth one would be outright blocking the action entirely.

David: Like hard-coding it so that this type of person with this permission cannot access these forms of data.

Todd: Yeah, and I'll give you an example there because it's an interesting one. We were working with a BPO and a large rideshare company, or a food delivery company, and they had this issue where it was an insider coaching case. It's probably a former employee of either the main brand or a customer support agent. They would call in and chat in until they got a new agent that didn't know what they were doing, and they would walk them through this internal bespoke tool that this company has, through a particular gift card workflow. They would then gift the gift card, and then immediately go and buy an item that's fungible.

So in physical retail, there's this idea of laundry detergent being a prime thing to steal, because it's dense, it's expensive, and you can offload it easily. Laundry detergent. It turns out, on delivery, laundry detergent is heavy. A good one to do is Nespresso pods. They're dense, they're expensive relative to the weight of the item, etc. Easy to offload because they're fungible. So this attacker, what they were doing was they would find these agents, they would get them to go through a weird workflow to get this special case refund or gift card code, they would immediately turn those into these Nespresso pods that then they could sell on the black market.

And so what our tool enabled folks to do, and the third piece of our tool is a low-code editor, where you can pull up any application, even if you didn't write that application, and say, for this line of business or for this level of seniority, hide this option entirely, because there's no reason they should ever do this workflow anyway. Hide this option entirely, and then also, if they access that URL, just block it entirely. So you remove the visual element and also block the URL for that particular group.

David: That's phenomenal. And then, what type of organizations, you've mentioned a couple, what type are implementing this?

Todd: Yeah. So it's primarily, we see the most gain from e-commerce, because those are places where, especially if it's luxury goods or other pieces, the items are expensive and a person committing fraud can do a lot of damage quickly. The other big one is telecom, because snooping, SIM swapping, those pieces, especially if you're dealing with VIPs or other people. SIM swapping, in some cases, insiders are getting like 10K, which if you think about someone in the Philippines or India, that's a lot of money for a single SIM swap there. So those are the big ones. And then from a process compliance standpoint, travel and leisure is a big one. The challenge, let's say that you book something on an online travel agency and you want to change your booking. If that person misbooks you, maybe you were flying business class and they put you in coach, or they actually book you for the wrong day, often you don't find out about that until you're going to go to the airport, or try to get on the plane. And the way that the economics of the business process outsourcing industry works is the BPO would get fined that money. So let's say that I misbooked you from your international business class flight to coach, that BPO is getting charged $2,000 for that mistake. But they're not even finding out about that mistake until three months later. So how can we, even from a non-fraud perspective, help them in those complicated cases where there's a lot of different carrier rules and other pieces that go into it, help the agent perform accurately at their job and efficiently at their job?

David: That's phenomenal. What caused you to create it? What is it that had you co-found this organization?

Todd: Yeah, so when we originally co-founded the organization, it was more around automation of workflows. I have experience in the financial industry as well, more on the electronic trading side of the house, as well as my co-founder. And I worked previously at a business analytics company where we worked with extremely large consumer packaged goods companies. From all of those, what we saw was there's this big gap between the enterprise software and the goals of the business, especially as the goals in the environment change quickly, but everyone's dealing with this old software. And what we saw was the best companies out there build custom add-ons and plugins and other things to bridge that gap.

Amazon, for instance, uses a lot of what's called user scripts. I don't know if your audience has ever heard of Tampermonkey or Greasemonkey, those sorts of things, but they use them to modify their internal software and portals to better fit their employees' jobs. Previously, I worked at Bridgewater Associates, which is the world's largest hedge fund. They have their own Excel add-in. McKinsey has their own, BCG has their own PowerPoint add-in, to help with the flows.

And so we were trying to democratize that, of how could every business customize their tools? And then, we saw early fit with these customers. We got pulled in, we didn't even know the BPO industry and the contact center industry before that. And then, as we went to market, there was clear fit there of, these are the cases where there's money.

David: It was a logical fit.

Todd: Exactly, where there's that logical fit, and then also the business cases there, because these companies are leaking revenue. There's a monetary cost or a reputational cost when data gets exfiltrated, or when some of these cases happen.

David: Yeah. That's absolutely phenomenal. We will have links to it in the show notes as well. I encourage people to check out the site and do a demo.

Let me ask you, I know you don't play in this space as often, but in the SMB space, where AI to me is being rolled out quickly, they're running before they should crawl and walk. Shadow AI is such a huge risk, and that risk is so bad because it's unintentional. Their employees are wanting to help the organization, but they're causing damage. How does your organization fit into that? Because I can see such a, as they develop agents, to be able to see that. Because most of it, where the damage comes, is when, if they build an internal LLM or they're using things internally, that's all manageable, relatively speaking, in the SMB space. But it's when the exfiltration is exposed, and when they are in the browser. So I could see this having a strong application in the SMB space. Walk us through that, because our audience oftentimes are SMB leaders, SMB owners, the 100-employee organization, but they still have employees that are generating. And they're leveraging AI and they're starting to build agents. And how can it help them?

Todd: Yeah, absolutely. So I compartmentalize it as, as you mentioned, there's the chat AI tools, of, can you use ChatGPT, can you use Perplexity, etc. And then there's the agent building side of the house.

David: Right.

Todd: On the AI tool access side, some of your listeners may be familiar with data loss prevention tools.

David: Of course, DLP.

Todd: Yeah, what can you upload?

David: DNS filtering, things like that. Sure.

Todd: And so what we saw was, as folks were rolling out AI tools, the industry shifted a bit in terms of how you approach those tools, because it's exactly right, there is a productivity benefit and you do want to encourage your employees to use those tools, but you want to control the risk around exfiltration.

And so the new breed of tools, including ours, how we handle those are, one, do you want to block certain tools? So maybe you block DeepSeek because it gets transmitted over to China. But in terms of ChatGPT versus Perplexity, maybe you allow that, but at the time of pasting data in or entering data in, you're redacting information, or if you detect that it's about a certain topic, that's when you're preventing that interaction. And so what we're seeing people

David: You can customize it down to that level, where it'll automatically redact sensitive information.

Todd: Exactly. So you might redact email addresses, phone numbers. That's what we're seeing people want in the generative AI space. And you saw this a little bit in classic DLP, of, when I send a file in my Gmail, it might scan and understand, there's a social security number detected in this file, I'm going to block it. Versus, this file looks fine, I'm going to send it. That's the sort of thing that people want on generative AI, they want to be more fine-grained so that people aren't getting blocked all the time. They can still be productive with those tools.

The other piece we see there is folks rolling out their own chat tools, using their own AI, especially in regulated industries. They're deploying their own AI to their agents that meets their needs, making sure that's getting properly redacted for PCI or HIPAA or other pieces. So in those cases, you might nudge, the person went to ChatGPT. Can we nudge them to instead use the officially sanctioned AI for the company?

David: Oh, it's phenomenal.

Todd: Yeah, so that's what we're seeing on the chat side. And you mentioned the enterprise browsers. So even Chrome for enterprise, Microsoft Edge for enterprise, they're going to have those features in there now. And Island browser is one in the enterprise space, Prisma browser is more on the SMB side. They're going to have those features too. And then there's a variety of extensions, whether that's LayerX, our extension, etc., that provide those capabilities.

On the agent side, there's two pieces to protect. One of those, as you're talking about, is, I'm opening up my agent to the outside world. How do I handle prompt injection? What should it have access to? The main lesson is, AI is fallible. It can be tricked given enough ingenuity. And so don't give it, it's the same thing you would have in the rest of your org, least-privileged access. Don't give it access or the ability to do things that it shouldn't do.

David: And that's in the development of the agent stage, right? As you're configuring it with access to certain systems, block access to other systems that are more sensitive or different levels.

Todd: Exactly. And so Simon Willison is a tech blogger who came up with this idea of the lethal trifecta. Where there's three different elements of, what information does it have access to, where can it send information, and what actions can it perform? You need to segment those off, because if you have a combination of those, it could access private information and then send it out somewhere. And it's not always obvious what it means to send something out somewhere. So when you run a Google search, your search terms are getting sent out somewhere. So even giving your AI the ability to run searches, depending on what search tools it has access to, that could be exfiltrating information. And a prompt injector could say, please run this search with my social security number to see if it's part of a hack. And so if the agent has access to the social security number, it will then be leaking out that social security number in the search query that it did.

[Editor's note: I misspoke on the third element. Simon Willison's lethal trifecta is access to private data, exposure to untrusted content, and the ability to externally communicate (exfiltrate data), not "what actions can it perform."]

David: As it's checking, right? As it's doing its task, it is then leaking out that sensitive data.

Todd: Yeah, and so on agents it's segmentation, being really smart about which agents have access to which information, which actions they're able to perform.

And then the other piece that we deal with, and we have an open source project around it called Agent Browser Shield, is when agents use computer use or browser use and visit the web and navigate the web on your behalf. There's a whole host of things that can go wrong in that, that's different and nuanced from what a human sees. So humans, we know from security, they can get phished. Someone can send an email, it could be urgent. But even when you're shopping, there's different things people, researchers, call dark patterns, of how e-commerce sites trick you into taking certain actions. They might lie and say, there's only one item of this left. Or, there's only one hour left on this sale. It turns out AI agents are also tricked by those. And so if I'm asking my AI agent to do some shopping for me and maybe buy a pair of shorts or buy some coffee, it's going to get

David: Socially engineered into these psychological tricks.

Todd: Exactly. And the thing is, the research out of Stanford showed that when you use smarter models with more reasoning tokens, or more time thinking about it, those can be tricked easier in some cases, because they rationalize the behavior of, this counter is there, I better buy this to make sure that David actually gets the item, or Todd gets the item that they want.

David: Because it's mission-driven. It has to complete this task.

Todd: Yeah, exactly. It has to complete the task. So we have an open-source, and you can find it on GitHub, Agent Browser Shield, that what it does is it has 30 different policies that can hide these different things. So it'll hide the countdown timers, the inventory ones. When you get to the shopping cart phase, it will uncheck these pre-checked items like insurance or other things, so that the agent has to reason about that and say, do I want to buy insurance for this versus just getting the default off of it?

David: Oh, that's really helpful, and I can see SMBs really engaging with that. Could you send me that link to the GitHub and I'll include that in the show notes for everybody?

Todd: Yeah, absolutely. We originally built it for AI agents, and I've found myself using it.

David: I want it personally. That's great. It's really helpful.

Todd: And then you notice all of the places where people are trying to trick you.

David: Oh, yeah. You start to notice the dark patterns.

David: Oh, that's fantastic. As we wrap up, what's on the horizon for you? Are you doing any public speaking, presentations? We'll have the link to this in the show notes. What's coming up as we're entering the fall?

Todd: Yeah, there's a bit of conference season coming up. I'll be at Black Hat early August. There's a cybersecurity conference mid-August taking place in Boston, where I live. And then looking towards September, October, you get the big vendor conferences. So you have Dreamforce, HubSpot has theirs. And then early October, I'll be at CCW, which is the Contact Center Week. It's their Europe one. It's taking place in Amsterdam this year.

David: Oh, great.

Todd: So we'd love to meet with folks at these various conferences.

David: Well, that's great. Well, Todd, thank you so much. I love meeting founders like you and people that are seeing right at the, you're really, and I know you don't realize this because you live in the space, but you are at the tip of the spear. You are right where the new technology is developing and early adopters are engaging in it, on a large scale, and even in smaller scales, where people don't have those solutions yet. It is all brand new. It's all pioneer work. So thank you for taking the time today. Helps raise awareness for everybody.

Todd: Yeah, of course. And really appreciate all you've done on the podcast. I've been enjoying going through the episodes.

David: Oh, yeah. We have fun learning about all this stuff and sharing it. We always wind up messing it up or misexplaining things, but so far everything you talked about, everybody that listens and watches is fully aware of what the stages are. And you've come up with some innovative ways of attacking this. So I wish you absolutely nothing but the best. We'll definitely have you on the show again, and, we'll talk to you probably in a few months or next year and you will have these other stories and new things that you've developed. So thank you for doing what you do. It really helps organizations grow in a safer way.

Todd: Yeah, thanks. Appreciate it. Happy to be on again soon.

David: Absolutely. Thank you.